Updated: 6 July 2026
What is AI governance and why is it a priority now? AI governance is the set of policies, processes, and oversight mechanisms that ensure artificial intelligence systems within an organisation are deployed and used in a lawful, ethical, and secure manner. The EU AI Act, in force since 2 Aug 2024, introduced obligations for organisations that use or deploy AI systems – particularly those classified as high-risk.
Alongside regulation, organisations face practical risks from uncontrolled shadow AI (employees using unapproved AI tools), data leakage into AI models, and a lack of transparency over algorithmically driven decisions.
AI governance – at a glance:
- The EU AI Act (2024) prohibits certain AI systems outright and imposes obligations on providers and deployers of high-risk AI systems – compliance obligations phase in progressively through to 2027
- Shadow AI is one of the most significant organisational risks of 2025 – employees use ChatGPT, Copilot, and other AI tools to process company data without IT or security’s knowledge or approval
- An AI system register – an inventory of every AI system in use across the organisation – is the foundation of any AI governance programme; without it, risk cannot be managed
- ISO/IEC 42001 (2023) is the first AI management system standard (AIMS) – certification is becoming a competitive differentiator for AI vendors and a compliance demonstration tool
- An AI risk assessment should identify AI-specific risks: hallucinations, bias, training data security, and accountability for algorithmic decisions
- Patronusec in the vCISO or IT Compliance Officer role helps organisations build an AI governance policy, an AI system register, and a risk assessment aligned with the EU AI Act and ISO/IEC 42001
Table of Contents
What obligations does the EU AI Act impose – and on whom?
The EU AI Act (Regulation EU 2024/1689) is the world’s first comprehensive AI regulation. It entered into force on 2 Aug 2024, but different obligations apply at different dates.
EU AI Act timeline:
- 2 Feb 2025: prohibition of “unacceptable risk” AI systems (social scoring, subliminal manipulation, mass biometric categorisation)
- 2 May 2025: obligations for GPAI (General Purpose AI) providers – foundation models
- 2 Aug 2026: full obligations for high-risk AI systems listed in Annex III
- 2 Aug 2027: obligations for AI systems regulated by other sector-specific legislation
Who is subject to the EU AI Act:
- Providers of AI systems – companies developing or placing AI systems on the EU market
- Deployers of AI systems – organisations using AI systems in a professional context
- Importers and distributors of AI systems from third countries
High-risk AI systems (Annex III):
Categories include: biometric identification of individuals, systems managing critical infrastructure, educational software assessing learners, recruitment and employee assessment systems, credit scoring in financial services and insurance, and systems supporting immigration and judicial decisions.
Obligations for deployers of high-risk systems (Art. 26):
- Use the system in accordance with the provider’s instructions
- Maintain human oversight of the AI system
- Monitor the system for risks and anomalies
- Notify the provider of incidents
- Retain system logs for six months
Patronusec Insight: Most organisations are “deployers” of AI systems – they use ChatGPT Enterprise, Microsoft Copilot, AI tools in HR, or scoring systems in finance. These organisations often do not know that the EU AI Act will impose specific obligations on them from 2026. The first step must be an inventory: which AI systems do we use, for which purposes, and does any qualify as high-risk? Without that inventory, compliance with the EU AI Act is not possible. We help clients build that inventory and risk assessment as part of our vCISO or IT Compliance Officer service.
How do you build an AI system register (AI inventory)?
An AI system register is the foundation of AI governance – without it, you cannot manage risk or satisfy the requirements of the EU AI Act.
What the AI system register should contain:
| Column | Content | Example |
|---|---|---|
| System name | Name of tool or AI product | ChatGPT Enterprise, Copilot for Microsoft 365 |
| Provider | Company supplying the system | OpenAI, Microsoft |
| Purpose | What the system is used for | Marketing content generation, CV screening |
| Users | Who uses the system | Marketing department, HR |
| Input data | What data is entered | Customer data, candidate data |
| Risk classification | EU AI Act risk level | Unacceptable / High / Limited / Minimal |
| Owner | Accountable person | Marketing Director, HR Manager |
| Approval status | Approved by IT/security | Yes / No / In progress |
| Review date | Most recent risk review | 15 Apr 2025 |
How to gather the inventory:
Most organisations do not know how many AI systems they are running. Shadow AI – tools used without IT’s knowledge – is the biggest challenge. A practical approach:
- Employee survey: what tools do you use for work? Which AI tools specifically?
- Review invoices and subscriptions: which SaaS tools are we paying for?
- Network traffic review (where available): which AI domains are being accessed?
- Department-by-department verification: HR, marketing, finance, sales, customer service
Need to build an AI system register and risk assessment aligned with the EU AI Act?
Patronusec runs AI governance workshops – AI system inventory, risk classification, and AI policy development. Delivered within 2 to 4 weeks.
Book an AI governance workshop
What is shadow AI and how do you manage the risks of uncontrolled AI use?
Shadow AI is the use of AI tools by employees without the knowledge, approval, or control of IT and security. In 2025, it is one of the most significant data security risks facing organisations.
The scale of the shadow AI problem:
Tools such as ChatGPT, Claude, Gemini, and Copilot are available free or at low cost and can be used without IT approval. Employees use them for content generation, data analysis, translation, and answering questions – often pasting in customer data, source code, financial results, and other confidential information.
Data entered into a public AI model may be used to train the provider’s models (depending on the terms of service), may be accessible to an attacker in the event of a provider breach, and may expose the organisation to UK GDPR violations (transfer of personal data to a third country without an adequate legal basis).
How to manage shadow AI:
- AI policy: a formal policy specifying which AI tools are approved, how AI may be used, and what must never be entered into AI systems (customer personal data, trade secrets, production source code).
- Approved AI tool stack: a list of approved AI tools – for example, Microsoft Copilot with EU data residency, GitHub Copilot Business with training-on-company-code disabled.
- Training: employees must understand the risks of entering data into public AI models – security awareness training must include AI as a dedicated module.
- Monitoring (where permissible): network traffic monitoring for connections to public AI APIs, particularly for employees with access to high-risk data.
Patronusec Insight: Shadow AI is not only a data security problem – it is an accountability problem. If an employee makes a business decision based on a ChatGPT response that is factually incorrect (a hallucination), who is liable? An AI policy must not only permit or prohibit AI tools; it must specify which decisions require human verification and who bears accountability for decisions made with AI assistance. This is precisely the human oversight requirement embedded in the EU AI Act for high-risk systems.
How does ISO/IEC 42001 support building an AI management system (AIMS)?
ISO/IEC 42001:2023 is the first management system standard for artificial intelligence (AI Management System, AIMS). Analogous to ISO 27001 for information security, ISO 42001 defines requirements for an AI management system within an organisation.
What ISO/IEC 42001 covers:
- Organisational context and interested parties (as in ISO 27001)
- Risk and impact assessment of AI systems
- AI governance policies
- AI system lifecycle management (from design through decommissioning)
- Transparency and explainability of algorithms
- Human oversight
- Accountability for AI decisions
When ISO/IEC 42001 certification makes sense:
- The organisation is an AI system provider and clients require evidence of AI risk management
- The organisation uses high-risk AI systems (EU AI Act) and certification helps demonstrate compliance
- The organisation is competing in tenders where an AI governance credential is a differentiator
ISO/IEC 42001 is compatible with ISO 27001 – organisations with ISO 27001 can integrate AIMS with their existing ISMS, benefiting from control coverage overlap.
FAQ – AI governance and the EU AI Act
Is using the free version of ChatGPT a UK GDPR violation?
Yes, if employees enter customer or employee personal data into the free version of ChatGPT, this is a potential UK GDPR violation. Personal data processed in ChatGPT is transferred to OpenAI (USA) – which requires an adequate legal basis (such as Standard Contractual Clauses). The free version of ChatGPT does not offer a Data Processing Agreement (DPA) required under UK GDPR. ChatGPT Enterprise or the API with a DPA may be an approved tool with the appropriate contract in place.
When do EU AI Act requirements for high-risk systems take effect?
Full requirements for high-risk AI systems listed in Annex III of the EU AI Act apply from 2 Aug 2026. However, organisations should begin preparation now – inventorying AI systems, assessing risk, and building an AI policy are processes that take months, not weeks.
Does every organisation need an AI policy?
Legally – not every organisation is obliged by the EU AI Act to have an AI policy (this depends on whether they use high-risk AI systems). However, from the perspective of risk management, UK GDPR, and accountability for AI-driven decisions – an AI policy is a de facto necessity for any organisation using AI in its operations, which today means most organisations.
How does the EU AI Act differ from UK GDPR in the context of AI?
UK GDPR regulates the processing of personal data – including by AI systems. UK GDPR Art. 22 already protects individuals against solely automated decisions that produce significant effects. The EU AI Act regulates more broadly – not only personal data, but all AI systems, including those that do not process personal data. The two frameworks are complementary.
How does Patronusec help with AI governance?
In the vCISO or IT Compliance Officer role, we help organisations conduct AI system inventories, classify risk against the EU AI Act, build AI policies and registers, and prepare for the requirements applying from 2026. We are not an AI tool provider – we help manage the risk associated with AI already deployed in the organisation.
Does ISO/IEC 42001 certification remove EU AI Act obligations?
It does not remove them – but it significantly simplifies demonstrating compliance. ISO/IEC 42001 provides an AI management framework covering many EU AI Act requirements (human oversight, documentation, risk assessment). ISO/IEC 42001 certification can serve as a credible argument with a supervisory authority when demonstrating AI management maturity.
AI governance and the EU AI Act – free consultation
Patronusec helps organisations build AI governance systems – from the first AI system inventory through policy and risk assessment to preparation for EU AI Act requirements from 2026. As a vCISO or IT Compliance Officer partner, we take ownership of the AI compliance programme.
In a free 30-minute consultation we will help you:
- Assess whether your organisation uses high-risk AI systems subject to the EU AI Act
- Understand the EU AI Act timeline and when you need to be ready
- Plan the development of an AI system register and AI governance policy
- Choose a support model: one-off workshops or ongoing vCISO/IT Compliance Officer support
Free consultation | vCISO | IT Compliance Officer | ISO 27001 | NIS2